
On August 12, 2026, Anthropic announced that the Claude in Chrome side panel now runs the same Claude Cowork session used across its desktop, web, and mobile apps. For users, this is more than moving a chat window. A multi-step task started in the browser can now continue on another surface with its context intact.
The new sessions are saved to account history, and skills and connectors can work in the browser. Claude in Chrome is a browser extension that can see the current page and take actions such as clicking links, typing, navigating, and filling forms using the user's existing logins. That gives Claude a way to work through internal dashboards, legacy systems, and vendor portals that do not have a direct integration.
Anthropic's example is a budget workflow: Claude can open several vendor portals, read invoice amounts and dates, and build a spreadsheet; the user can then continue in the desktop app to add local files, or pick up the same conversation on the web or mobile app. The product focus is therefore shifting from a single answer toward continuous work across websites, tools, and devices.
Availability is still rolling out. Anthropic says the feature is available to Max and Team users now, with Pro access coming over the next few weeks. On Enterprise plans, Claude in Chrome is off by default; administrators can enable it and restrict use to approved domains. The capability is currently limited to the Chrome side panel, not other Chromium browsers or mobile browsers, and the desktop app is still required for local files and other applications.
Anthropic also identifies prompt injection as the main risk. Malicious instructions can be hidden in a webpage, email, or document and redirect an agent toward actions the user did not request. The company says it added a check on Claude's own actions: even with automatically approve enabled, a separate check reviews consequential actions such as submitting a form, sending a message, or downloading a file against the original task. Purchases and sharing personal data still require confirmation. Anthropic says these measures reduce risk but cannot eliminate prompt injection.
The broader product signal is that an agent's context is moving from a single device to an account-level session. That is an inference from the feature design: once work can start in a browser and finish in a desktop or mobile app, the important product layer is not only the model response but also state, tool connections, and human approval points. Teams adopting browser agents should still begin with trusted sites and explicit permissions, keeping sends, submissions, downloads, and data sharing behind reviewable checkpoints.



